More on critical thinking and as I say to interview your users in a way that they think you're just having a casual conversation with them.

If you go to a new job and you see open ceiling tiles it's probably a good bet that there's a leak there. Or, was.
The tile wasn't replaced because they're expensive or someone was just lazy and didn't want to replace it.

but if you speak to people and ask why it's open they're going to tell you the story surrounding it.
By speaking to them and letting them tell stories in a way that makes them think they're teaching you something you can get an inkling as to what type of environment you're actually in.

If you interrogate them they're going to clam up.
This is what we call social engineering. Getting information in a clever way which doesn't come across as antagonizing.

it also tells you what sorts of information people are willing to let go to people that they don't know.
you just started this job and in the first hour you got an open ceiling tile a leak that wasn't properly fixed and everyone's telling you how your predecessor was an absolute idiot.

The takeaway isn't that they were an idiot.
The takeaway is that you've got people running their mouths when they shouldn't and exposing sensitive information.

if they'll tell you after an hour of employment they can easily tell someone else that doesn't work there too.
They also don't seem to care about fire hazards.

Just some food for thought based on actual experience. Way too much experience that I'm not comfortable with.
You can follow @blackroomsec.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.